- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
| Commands | Descriptions |
|---|---|
| vpn tu | VPN utility, allows you to rekey vpn |
| vpn ipafile_check ipassignment.conf detail | Verifies the ipassignment.conf file |
| dtps lic | show desktop policy license status |
| cpstat -f all polsrv | show status of the dtps |
| vpn shell | Start the VPN shell |
| vpn shell /tunnels/delete/IKE/peer/[peer ip] | delete IKE SA |
| vpn shell /tunnels/delete/IPsec/peer/[peer ip] | delete Phase 2 SA |
| vpn shell /show/tunnels/ike/peer/[peer ip] | show IKE SA |
| vpn shell /show/tunnels/ipsec/peer/[peer ip] | show Phase 2 SA |
| vpn shell show interface detailed [VTI name] | show VTI detail |
| vpn debug ikeon|ikeoff | Debug IKE into $FWDIR/log/ike.elg. Analyze ike.elg with the IKEView tool |
| vpn debug on|off | Debug VPN into $FWDIR/log/vpnd.elg. Analyze vpnd.elg with the IKEView tool |
| vpn debug trunc | Truncate and stamp logs, enable IKE & VPN debug |
| vpn drv stat | Show status of VPN-1 kernel module |
| vpn overlap_encdom | Show, if any, overlapping VPN domains |
| vpn macutil <user> | Show MAC for Secure Remote user <user> |
| vpn ver [-k] | Check VPN-1 major and minor version as well as build number and latest hotfix. Use -k for kernal version |
Nice summary. Speaking about debug commands procedure is written in more SK articles. At least good one for start is the sk33327 - How to generate a valid VPN debug, IKE debug and FW Monitor
apparently not anymore
You kick and ancient topic from 2018.
Here is the relevant SK made for this time period:
https://support.checkpoint.com/results/sk/sk180488
Hello,
Is there any command that captures the traffic on both P1 and P2?
Is it possible to check it through the CLI, or do you necessarily have to capture the data and check it in IKEView Tool?
It's possible one of the various VPN kernel debugs might show you this information.
Capturing the relevant traffic and viewing it into IKEView is probably quicker/easier.
Hello, @PhoneBoy
When you have VPN tunnel errors with “intermittent” drops that occurred a couple of days ago, is it possible to detect the root cause of these problems in the ‘messages’ or “dmesg” files of our FW?
Or is this information stored somewhere else?
Cheers.
Issues with the VPN would not likely manifest itself in Gaia OS logs.
Possibly cpview has something and it might also show in the regular access policy logs (depending on the nature of the failure).
Good commands and lastly IKE Info Viewer is the best tool to troubleshoot VPN.
So looking at the information on the "IKEView Tool" in sk30994, it seems it can only display information captured in a debug. Is there a way to see in realtime the remaining key lifetimes on Phase1 and Phase2 SAs, or other details such as Phase2 SA local and remote identities? This could easily be done on ASA, but I can't seem to find it on Check Point gateways.
Same Question!
| Commands | Descriptions |
|---|---|
| vpn tu | VPN utility, allows you to rekey vpn |
| vpn ipafile_check ipassignment.conf detail | Verifies the ipassignment.conf file |
| dtps lic | show desktop policy license status |
| cpstat -f all polsrv | show status of the dtps |
| vpn shell | Start the VPN shell |
| vpn shell /tunnels/delete/IKE/peer/[peer ip] | delete IKE SA |
| vpn shell /tunnels/delete/IPsec/peer/[peer ip] | delete Phase 2 SA |
| vpn shell /show/tunnels/ike/peer/[peer ip] | show IKE SA |
| vpn shell /show/tunnels/ipsec/peer/[peer ip] | show Phase 2 SA |
| vpn shell show interface detailed [VTI name] | show VTI detail |
| vpn debug ikeon|ikeoff | Debug IKE into $FWDIR/log/ike.elg. Analyze ike.elg with the IKEView tool |
| vpn debug on|off | Debug VPN into $FWDIR/log/vpnd.elg. Analyze vpnd.elg with the IKEView tool |
| vpn debug trunc | Truncate and stamp logs, enable IKE & VPN debug |
| vpn drv stat | Show status of VPN-1 kernel module |
| vpn |
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 64 | |
| 24 | |
| 13 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY